Privacy Policy

Lumis: Student Planner · Coral Code · Last updated July 26, 2026

Lumis is built by two students, and we treat your data the way we'd want ours treated: we collect what the app needs to work, we don't sell it, and you can delete it.

What we collect

  • Account information — your email address and a securely hashed password, used to create and sign in to your account.
  • Course content you upload — syllabi, lecture notes, slides, readings, and study materials. These are processed by AI to build your calendar, reminders, flashcards, quizzes, and study guides.
  • Usage data — basic analytics about how the app is used (such as which features are opened and AI usage counts), associated with your account, used to fix problems and improve the app.

Your courses, assignments, notes, and study sessions are stored on your device. We do not collect your location, contacts, photos (other than syllabus images you choose to upload), or advertising identifiers.

The waitlist on this website

If you join the waitlist at lumisapp.org, we store the email address you enter, the school name if you provide one, whether you asked for a TestFlight beta invite, and the date you signed up. We also store a one-way hash of your IP address, which we use only to stop the form being spammed — it isn't used to identify you.

We use waitlist entries for one thing: emailing you about the Lumis beta and launch. It is not a marketing list we sell, rent, or share, and it isn't connected to an app account unless you create one. Ask us at privacy@lumisapp.org and we'll delete your entry — no account needed.

How your content is processed

When you upload a syllabus or generate study materials, that content is sent to our server and processed by an AI model provider (currently OpenAI) to produce your results. Content is used to serve you — it is not used to train models by us, and we do not sell or share it for advertising.

Service providers

We use a small number of infrastructure providers to run Lumis: Vercel (application hosting), Supabase (database for accounts, usage data, and waitlist entries), and OpenAI (AI processing of content you submit). Each receives only what's needed to provide its function.

Payments

Premium subscriptions are handled entirely by Apple through the App Store. We never see your payment details.

Deleting your data: you can delete your account and associated server data from within the app, or by emailing privacy@lumisapp.org from your account email. Deleting the app from your phone removes all on-device course data.

Data retention & security

Account and usage data are kept while your account is active and deleted on request. Waitlist entries are kept until launch or until you ask us to remove them. Passwords are stored only as salted hashes, and connections to our servers are encrypted in transit.

Children

Lumis is intended for college and high-school students aged 13 and up and is not directed at children under 13.

Changes

If our practices change, we'll update this page and the "last updated" date above, and material changes will be called out in the app.

Contact

Questions about privacy: privacy@lumisapp.org.